Lucene search

K
vulnrichmentAppleVULNRICHMENT:CVE-2023-42954
HistoryMar 21, 2024 - 10:24 p.m.

CVE-2023-42954

2024-03-2122:24:36
apple
github.com
3
filemaker server
privilege escalation
sensitive information
front-end websites
admin console
administrator role
information requests

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*"
    ],
    "vendor": "claris",
    "product": "filemaker_server",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "20.3.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-42954